1.6 Risk Categories and Risk Management vs. Risk Assessment
Key Takeaways
- PECB Domain 1 explicitly names four risk types: strategic, financial, compliance, and operational risk.
- Systematic risk is market-wide and non-diversifiable (interest rate, exchange, inflation), whereas unsystematic risk is entity-specific and diversifiable (operational, business, credit risk of one firm).
- Risk assessment is only the middle portion of the ISO 31000 process: risk identification, risk analysis, and risk evaluation.
- Risk management is the whole discipline - principles, framework, and process - and includes treatment, monitoring, recording, reporting, and communication.
- Confusing risk management with risk assessment is a named PECB competency, and a frequent source of distractors.
1.6 Risk Categories and Risk Management vs. Risk Assessment
Two Domain 1 competencies are examined together often enough to be worth studying together: the ability to distinguish between various types of risk, and the ability to distinguish between risk management and the risk assessment process. Both are definitional, both are cheap marks, and both are frequently lost to plausible-sounding distractors.
The Four Risk Types Named in Domain 1
PECB's Domain 1 knowledge statements explicitly list strategic, financial, compliance, and operational risk. These are the categories an ISO 31000 risk taxonomy is normally built on.
| Risk type | Definition | Typical examples | Usual owner |
|---|---|---|---|
| Strategic | Risk arising from the organization's chosen direction and its ability to execute it | Failed market entry, disruptive competitor, poor merger integration, obsolete business model | Board / CEO |
| Financial | Risk to capital, liquidity, earnings, and asset values | Credit default, liquidity shortfall, currency and interest-rate movement, investment loss | CFO / Treasurer |
| Compliance | Risk of breaching laws, regulations, contracts, or internal policy | GDPR breach, sanctions violation, licence loss, contractual non-performance | Chief Compliance Officer |
| Operational | Risk from inadequate or failed internal processes, people, systems, or external events | Process failure, fraud, system outage, supply chain disruption, safety incident | Operational management |
Many taxonomies add reputational, cyber, project, and ESG/climate risk. These are usually treated as cross-cutting consequences or sub-categories rather than as a fifth peer category — reputational damage, for example, is normally a consequence of a compliance, operational, or strategic event rather than a source in its own right.
Systematic vs. Unsystematic Risk
This pair comes from financial risk theory and appears in PECB scenario questions.
- Systematic risk (also called market risk or non-diversifiable risk) affects an entire market or economy. No amount of portfolio diversification removes it. Examples: interest rate risk, exchange rate risk, inflation risk, recession, political and geopolitical risk.
- Unsystematic risk (also called specific, idiosyncratic, or diversifiable risk) is confined to one entity, sector, or asset. It can be materially reduced by diversification. Examples: operational risk, business risk, a single firm's credit risk, a product recall, a key-person departure, a plant fire.
Exam Tip: A published PECB sample question asks for an example of unsystematic risk, offering exchange risk, interest rate risk, and operational risk. The answer is operational risk — exchange and interest rate risk are both market-wide and therefore systematic.
Pure vs. Speculative Risk
A second classical pair worth holding:
- Pure risk admits only loss or no loss — fire, theft, natural catastrophe, workplace injury. Pure risks are the classic subject of insurance.
- Speculative risk admits gain, loss, or no change — a new product launch, an acquisition, a currency position, an R&D programme.
ISO 31000:2018 spans both. Because risk is defined as the effect of uncertainty on objectives, and an effect is a deviation from the expected that may be positive, negative, or both, ISO 31000 explicitly refuses to restrict risk management to pure downside risk. This is why taking or increasing risk to pursue an opportunity is one of the standard's treatment options.
Risk Management vs. Risk Assessment
This is the distinction PECB names as its own competency, and it is the one candidates most often get wrong under time pressure.
Risk assessment is defined in ISO 31000:2018 Clause 6.4 as the overall process of risk identification, risk analysis, and risk evaluation — three steps and no more. It answers: what could happen, how bad and how likely is it, and does it matter enough to act on?
Risk management is the whole discipline: coordinated activities to direct and control an organization with regard to risk. Under ISO 31000 it comprises three architectural layers:
- Principles (Clause 4) — the eight characteristics of effective risk management, centred on value creation and protection.
- Framework (Clause 5) — leadership and commitment, integration, design, implementation, evaluation, improvement.
- Process (Clause 6) — communication and consultation; scope, context and criteria; risk assessment; risk treatment; monitoring and review; recording and reporting.
| Risk assessment | Risk management | |
|---|---|---|
| Scope | Three activities within one process step | Principles, framework, and the entire process |
| Clause | 6.4 only | The whole standard |
| Includes treatment? | No | Yes |
| Includes governance and leadership? | No | Yes |
| Output | A prioritized, evaluated risk picture | A sustained, integrated organizational capability |
Exam Trap: A distractor that describes "identifying, analyzing, evaluating, and treating risks" is describing neither term cleanly — treatment sits outside risk assessment. Likewise, an option claiming risk management is "a synonym for risk assessment" is always wrong.
The Main Elements of Risk Management
When a question asks for the main elements of risk management under ISO 31000, the expected answer is the tripartite architecture — principles, framework, process — supported by:
- A defined risk management policy approved by top management.
- Assigned roles, authorities, responsibilities, and accountabilities, including risk owners.
- Allocated resources — people, budget, tools, information, and training.
- Established risk criteria reflecting appetite, objectives, and obligations.
- Communication and consultation running throughout, not bolted on at the end.
- Monitoring, review, recording, and reporting to close the improvement loop.
Which of the following is an example of unsystematic risk?
Under ISO 31000:2018, which activities make up the risk assessment process?
A regulator fines an organization after it fails to file a mandatory disclosure required by statute. Using the four risk categories named in the PECB Domain 1 syllabus, how is this risk best classified?